|
196961
|
8.1 |
HIGH
Network
|
marvell
|
qconvergeconslole_gui
|
Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a user-supplied path p…
|
CWE-22
Path Traversal
|
CVE-2020-5804
|
2024-11-21 14:34 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196962
|
6.5 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and e…
|
CWE-22
Path Traversal
|
CVE-2020-5811
|
2024-11-21 14:34 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196963
|
5.4 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5810
|
2024-11-21 14:34 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196964
|
5.4 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, …
|
CWE-79
Cross-site Scripting
|
CVE-2020-5809
|
2024-11-21 14:34 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196965
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_diagnostics
|
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log en…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-5807
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196966
|
5.5 |
MEDIUM
Local
|
rockwellautomation
|
factorytalk_linx
|
An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-5806
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196967
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_linx
|
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandle…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-5802
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196968
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_linx
|
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in p…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-5801
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196969
|
4.8 |
MEDIUM
Network
|
nec
|
ism_server
|
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to …
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5684
|
2024-11-21 14:34 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196970
|
7.8 |
HIGH
Local
|
epson
|
offirio_synergyware_printdirector epsonnet_setupmanager
|
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5681
|
2024-11-21 14:34 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|